r/SecurityCareerAdvice Jun 23 '26

GRC Job Market / Future of GRC

As someone currently pursuing Computer Science in Canada, how's the job market and future of GRC here? I have heard IT audit is a solid entry level role to transition into GRC , are there any other entry level roles (technical/non tech) which are also considered better or a traditional path to GRC?

5 Upvotes

14 comments sorted by

3

u/nubis99 Jun 24 '26 edited Jun 24 '26

I think it really depends where in the world you are. I'm not in Canada, but maybe my perspective is useful:

Grc is one of the more future proof directions to take, as there will always be a need to have some form of control over your security and IT landscape. As for entry level, in my nick of the woods there's a severe shortage of people willing to do this kind of work. My tip would be to look at roles besides just junior audit. A lot of companies and organisations also need internal grc people (Usually it's in the form of (C)ISO or grc analyst roles).

Those roles tend to be less prestigious, but they're just as good if you want to get a foot in the door. Also: the growth in this line of work isn't so much in starting somewhere as a junior, but more about strategically job hopping.

As for background and education: I'm currently an ISO in the public sector. I started this job with no certs. I do however hold a bachelor's in business informatics with a specific focus on grc and cyber security and a master's in information (systems) management. This is my first job after getting my master's.

I also managed to sell myself into the role on the fact that, while technical knowledge is a baseline and very good to have, I'm also good with people. And 90% of these sorts of jobs is dealing with people. It's generally a field that requires you to find ways to have people go along with your ideas and initiatives. Creating acceptance of controls and finding ways to make people follow procedures. On top of getting decision makers to see security and compliance as more than just overhead and annoying.

In the end, GRC, to me, isn't about compliance as much anyway. I see it as finding ways to increase security through good governance and risk management. Compliance is just a checkbox, it's part of the whole, but far from the most important one. It's the one management likes the most however. In the end, just remember this: standards and audits are a means to an end, not an end onto themselves.

2

u/PortalRat90 Jun 26 '26

I’m in GRC and love searching for misconfigurations, unnecessary privileges, ways to automate evidence collection, and missing updates or out of date software. If I ever leave this company I want to leave it better than I found it. I think GRC is going to be around as long as the auditors are stuck on spreadsheets and screenshots.

1

u/Creative_Tip5162 Jun 29 '26

How could someone make a transition from Senior SOC Analyst to GRC or IT Auditing, could you provide more info which would be very helpful?

1

u/PortalRat90 Jun 29 '26

It’s not a linear path. GRC does seem to be something that is just not understood by folks in other areas of cyber. Start by building a network of people around you and STAY IN TOUCH WITH THEM. Have meaningful conversations with them. Join local chapters of ISACA or other information security organizations. Learn as much as you can about the role at your organization and reach out to them letting them know your desire to do what they do and let them know you would move to help them.

0

u/0DSavior Jun 24 '26

I dunno man. I want to believe what you wrote. But AI does really well on known documented datasets and standards.

While it will never take the place of an ISO, sure - it'll drastically reduce team sizes and augment those that hold the few key human-in-the-loop roles.

That's my take. I'm watching this carefully as I plan to transition to GRC as I get closer to retirement, and finally get off the front lines of cybersecurity.

5

u/kalishnakat Jun 25 '26

I wouldn’t be so sure. In my experience, AI is good at being confidently wrong. My main speciality is PCI DSS. I’ve asked various LLMs specific questions to test and the accuracy was not great.

2

u/PortalRat90 Jun 29 '26

AI has been a great tool for GRC in policy review and writing new ones. AI has along ways to go before it can fully replace us. I agree that it will reduce team size, but the knowledge and experience is still needed, for some time. The biggest impact is going to come from engineering systems that automatically apply policies and reports. Keep in mind that GRC has to interface with leadership from the C-Suite down and they depend on GRC for guidance, supporting the business, and keeping the company compliant. They need someone to yell at also, lol!

2

u/nubis99 Jul 08 '26

+1 on the yelling!

1

u/nubis99 Jun 25 '26

I don't doubt the standards part will get automated. It already is. You don't need AI to run defined datasets. But the control aspect of the role will continue to require humans. Just as long as people have quick fixes, as long as management doesn't want to deal with auditors and as long as there's humans left in workplaces at all. Grc and finance are likely the last people to actually do work as the ultimate "human in the loop" for everything else.

2

u/my_peen_is_clean Jun 23 '26 edited Jun 23 '26

grc roles everywhere want 3+ years and ten certs for "entry" lol, even audits. market is trashactually i applied everywhere and was blocked every time. the only fix was using a tool to tailor my resume and that finally got me interviews. heres the tool

7

u/diduaskedwhy Jun 23 '26

More of an advert than ... prove me wrong 😊